Hackers are exploiting two critical Citrix NetScaler zero-days

https://media.thenextweb.com/2026/09/server-rack-ethernet-cables-green-light.jpg

Attackers are exploiting two critical flaws in Citrix NetScaler ADC and NetScaler Gateway. Companies use the devices to give staff remote access to internal networks. Citrix confirmed the attacks in a security bulletin on Sunday and released fixes. Both flaws were exploited before a patch existed.

“Exploits of CVE-2026-88771 and CVE-2026-88772 on unmitigated NetScaler deployments have been observed,” Citrix said.

CVE-2026-88771 lets an attacker run commands without logging in. It affects all NetScaler ADC and Gateway deployments, including the default setup. CVE-2026-88772 is a memory overflow that can lead to remote code execution or a crash. It needs a setting called DTLS, which is on by default on VPN servers. Both score 9.5 out of 10 for severity.

The bulletin covers eight flaws in total. Fixed versions are 14.1-73.37 and 13.1-64.23, plus matching FIPS builds. Citrix is upgrading the cloud services it manages itself.

Government warnings

The US Cybersecurity and...

Copyright of this story solely belongs to thenextweb.com. To see the full text click HERE

Read more